Mobile device control device, mobile device control method and program
The mobile control device addresses false tampering detections by suspending specified functions during active use, ensuring continued operation until a standby state is reached, thus improving traffic safety and user convenience.
Patent Information
- Application Number
- JP2024050799
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-27
- Publication Date
- 2025-10-09
- Estimated Expiration
- 2044-03-27
AI Technical Summary
Mobile control devices face frequent false detections of software tampering during secure boot processing, leading to unintended interruptions in device operation, which is a concern for traffic safety and user convenience.
A mobile control device with a tamper recognition unit that performs secure boot processes and a tamper response unit to suspend specified functions until the device enters a standby state upon detecting tampering, with adjusted judgment frequencies and rates based on device activation state and function type.
Prevents interruptions due to false software tampering detections by maintaining functionality until a safe state is reached, enhancing traffic safety and user convenience.
Smart Images

Figure 2025150094000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a mobile object control device, a mobile object control method, and a program. [Background technology]
[0002] Conventionally, a secure boot technology has been known in which, when starting up an electronic device, whether or not software such as firmware has been tampered with is verified, and the device is started up if it is verified that there has been no tampering (see, for example, Patent Document 1). Patent Document 1 discloses a technology for shortening the start-up time by simultaneously verifying that multiple pieces of firmware that are the subject of verification for whether or not they have been tampered have not been tampered with. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Patent Publication No. 2021-2168 Summary of the Invention [Problem to be solved by the invention]
[0004] Mobile control devices, which are an example of electronic devices, also perform secure boot processing to improve traffic safety. Secure boot processing is performed not only when the mobile device is started but also in the background while the device is operating. While performing secure boot processing while the mobile device is operating in this manner can improve software reliability, there is a concern that the increased frequency of secure boot processing increases the likelihood of false detection of tampering. When software tampering is detected through secure boot processing, the operation of the mobile device is stopped. However, if a false detection occurs, the operation of the mobile device is also stopped, which can cause inconvenience to the user, interrupting use of the mobile device. Therefore, an objective of the present application is to prevent interruption of use of the mobile device due to false detection of software tampering. The present application aims to improve safety in order to solve the above-mentioned problems, and by extension, to further improve traffic safety and contribute to the development of a sustainable transportation system. [Means for solving the problem]
[0005] A first aspect for achieving the above object is a mobile body control device that includes a tamper recognition unit that executes a secure boot process to verify whether software stored in a memory unit provided in a mobile body has been tampered with and recognizes tampering of the software, and a tamper response unit that executes the secure boot process by the tamper recognition unit when the mobile body is in an activated state, and when the tamper recognition unit recognizes tampering of the software related to a specified function of the mobile body, executes a tamper response suspension process that keeps the specified function usable until the mobile body enters a standby state, and disables the use of the specified function after the mobile body enters a standby state.
[0006] In the above-mentioned mobile control device, the tampering recognition unit may be configured to execute the secure boot process multiple times and confirm the recognition of tampering of the software when tampering is detected consecutively by the secure boot process a predetermined number of times or more, or when the proportion of the number of times tampering is detected among the multiple executions of the secure boot process is a predetermined proportion or more.
[0007] In the above-mentioned mobile body control device, the tampering recognition unit may be configured to set the number of judgments when the mobile body is in an activated state to be greater than the number of judgments when the mobile body is in a standby state, and to set the judgment rate when the mobile body is in an activated state to be greater than the judgment rate when the mobile body is in a standby state.
[0008] In the above-described mobile object control device, the tamper recognition unit may be configured to change the number of times of judgment and the judgment rate in accordance with the predetermined function.
[0009] In the above-mentioned mobile body control device, the tampering response unit may be configured to determine whether or not to execute the tampering response pending process depending on the type of the specified function when the secure boot process is executed by the tampering recognition unit when the mobile body is in an activated state and the tampering recognition unit recognizes tampering of the software related to the specified function of the mobile body.
[0010] In the above-mentioned mobile body control device, the mobile body is a vehicle and is equipped with a mobile body position recognition unit that recognizes the position of the mobile body, and the tampering response unit may be configured such that when the mobile body is in an activated state and the mobile body position recognition unit recognizes that the mobile body is located outside a road, the secure boot processing is executed by the tampering recognition unit, and when the tampering recognition unit recognizes tampering of the software related to the specified function of the mobile body, the tampering response suspension processing is not executed and the specified function is disabled.
[0011] The above-mentioned mobile body control device may be configured to include a tampering notification unit that outputs warning information about tampering with the software from an alarm device used in the mobile body when the tampering recognition unit recognizes tampering with the software.
[0012] The above-mentioned mobile body control device may be configured to include a tampering notification unit that, when the tampering recognition unit recognizes that the software has been tampered with, sends warning information about the software tampering to a user terminal used by a user of the mobile body.
[0013] A second aspect for achieving the above object is a mobile body control method executed by a computer, the mobile body control method including: a tampering recognition step of executing a secure boot process to verify whether software stored in a memory unit provided in the mobile body has been tampered with, and recognizing tampering of the software; and a tampering response step of executing the secure boot process by the tampering recognition step when the mobile body is in an activated state, and if tampering of the software related to a specified function of the mobile body is recognized by the tampering recognition step, executing a tampering response suspension process to maintain a state in which the specified function can be used until the mobile body enters a standby state, and disabling the use of the specified function after the mobile body enters a standby state.
[0014] A third aspect for achieving the above object is a program that causes a computer to function as a tampering recognition unit that executes a secure boot process to verify whether software stored in a memory unit provided in a mobile object has been tampered with and recognizes tampering with the software, and a tampering response unit that executes the secure boot process by the tampering recognition unit when the mobile object is in an activated state, and, if the tampering recognition unit recognizes tampering with the software related to a specified function of the mobile object, executes a tampering response suspension process that keeps the specified function usable until the mobile object enters a standby state, and disables the use of the specified function of the mobile object after the mobile object enters a standby state. [Effects of the Invention]
[0015] According to the above mobile object control device, mobile object control method, and program, it is possible to prevent interruption of use of a mobile object due to erroneous detection of software tampering. [Brief explanation of the drawings]
[0016] [Figure 1] FIG. 1 is a configuration diagram of a mobile object control device. [Figure 2] FIG. 2 is a first flowchart of the ECU software tampering monitoring process. [Figure 3] FIG. 3 is a second flowchart of the ECU software tampering monitoring process. DETAILED DESCRIPTION OF THE INVENTION
[0017] [1. Configuration of mobile control device] The configuration of a mobile body control device 1 of this embodiment will be described with reference to FIG. 1. The mobile body control device 1 is mounted on a vehicle 100 and controls the operation of the vehicle 100. The vehicle 100 corresponds to a mobile body in the present disclosure. The mobile body in the present disclosure may be an aircraft, a ship, or the like, in addition to a vehicle. The vehicle 100 is equipped with an SS (start / stop) switch 2 that instructs starting and stopping (power on and power off) the vehicle 100, a communication unit 3, a navigation device 4, and a display 5. In response to a start operation (start operation) of the SS switch 2, the vehicle 100 enters a start state in which it is capable of traveling, and in response to a stop operation (stop operation) of the SS switch, the vehicle 100 enters a standby state in which it is unable to travel.
[0018] The communication unit 3 communicates with the mobile object management server 210 and a user terminal 90 used by a user U of the mobile object via the communication network 200, and also performs short-range wireless communication with the user terminal 90 using Bluetooth (registered trademark), Wifi (registered trademark), etc. The navigation device 4 has a GNSS (Global Navigation Satellite System) sensor that detects the position of the vehicle 100, and provides route guidance to the destination, etc.
[0019] The mobile object control device 1 includes a central ECU (Electronic Control Unit) 10, gateway ECUs 50a and 50b, and local ECUs 51a to 51f. The central ECU 10 is connected to the gateway ECU 50a by a communication line 40a, and is also connected to the gateway ECU 50b by a communication line 40b.
[0020] The gateway ECU 50a is connected to a plurality of local ECUs 51a to 51c via a communication line 41a, and the gateway ECU 50b is connected to a plurality of local ECUs 51d1 to 51f via a communication line 41b. The local ECUs 51a to 51c control the operation of on-board devices 71 to 73 provided in the vehicle 100. The on-board devices 71 to 73 include, for example, drive sources such as an engine or an electric motor, driving operation devices such as a steering wheel, a brake pedal, and an accelerator pedal, lighting devices such as headlights, accessories such as wipers, electrically operated equipment such as power sliding doors and power windows, and an air conditioner. In addition, the local ECU 51d controls the operation of the communication unit 3, the local ECU 51e controls the operation of the navigation device 4, and the local ECU 51f controls the operation of the display 5.
[0021] Hereinafter, the gateway ECU 50a and the gateway ECU 50b will be collectively referred to as the gateway ECU 50, and the local ECUs 51a to 51f will be collectively referred to as the local ECU 51. Furthermore, devices connected to the local ECU 51 will be collectively referred to as the in-vehicle devices. The central ECU 10, the gateway ECU 50, and the local ECU 51 are control units equipped with a processor, a memory, an interface circuit, etc.
[0022] The multiple local ECUs 51 connected to the gateway ECU 50 are grouped according to the functions and locations of the in-vehicle devices connected to the local ECUs 51. While two gateway ECUs 50a and 50b are illustrated in FIG. 1, three or more gateway ECUs 50 may be provided. Furthermore, the number of in-vehicle devices connected to the local ECU 51 may be two or more.
[0023] The central ECU 10 manages the mobile object 100 by OTA (Over The Air), downloads new versions of software (update software) for the local ECU 51 from the mobile object management server 210, and updates the software of the local ECU 51. The central ECU 10 also monitors whether or not software stored in the memory of the local ECU 51 has been tampered with. The following describes the process executed by the central ECU 10 to recognize whether software in the local ECU 51 has been tampered with and the response process when software tampering is detected.
[0024] The central ECU 10 includes a processor 20, a memory 30, etc., and the memory 30 stores a program 31 for controlling the central ECU 10. The processor 20 corresponds to the computer of the present disclosure. The processor 20 reads and executes the program 31, thereby functioning as a communication control unit 21, a tampering recognition unit 22, a tampering response unit 23, a mobile object position recognition unit 24, and a tampering notification unit 25.
[0025] The process executed by the tamper recognition unit 22 corresponds to the tamper recognition step in the mobile object control method of the present disclosure, and the process executed by the tamper response unit 23 corresponds to the tamper response step in the mobile object control method of the present disclosure.
[0026] The communication control unit 21 controls communication between the mobile object management server 210 and the user terminal 90 via the communication unit 3. The tampering detection unit 22 executes a secure boot process to verify whether or not the software stored in the memory of the local ECU 51 has been tampered with, and detects whether or not the software has been tampered with. When the tampering detection unit 22 detects that the software in the local ECU 51 has been tampered with, the tampering response unit 23 executes a process to disable the use of predetermined functions realized by the operation of the software. Details of this process will be described later.
[0027] The mobile object position recognition unit 24 communicates with the navigation device 4 to recognize the position of the vehicle 100 detected by the GNSS sensor of the navigation device 4. When the tampering recognition unit 22 recognizes that the local software has been tampered with, the tampering notification unit 25 transmits tampering notification information to the display 5 to notify that the local software has been tampered with, and causes the display 5 to display a tampering notification screen indicating that the local software has been tampered with. Furthermore, when the tampering recognition unit 22 recognizes that the local software has been tampered with, the tampering notification unit 25 transmits tampering notification information to the user terminal 90 to notify that the local software has been tampered with, and causes the display unit of the user terminal 90 to display a tampering notification screen indicating that the local software has been tampered with. [2. Software tampering monitoring process] The procedure of the process of monitoring software tampering in the local ECUs 51 executed by the mobile object control device 1 will be described with reference to the flowcharts shown in Figures 2 and 3. When the vehicle 100 is in an activated state and when the vehicle 100 is in a standby state, the mobile object control device 1 executes the process according to the flowcharts in Figures 2 and 3 at predetermined timings for the software stored in the memories of the multiple local ECUs 51 to monitor for tampering. The timing for executing the secure boot process is set, for example, when the vehicle 100 enters a standby state by a stop operation of the SS switch 2, or whenever a predetermined time has elapsed.
[0028] 2, the tampering recognition unit 22 resets a counter variable CT (0→CT) for counting the number of times tampering has been detected. In the following step S2, the tampering recognition unit 22 executes secure boot processing on the software of the local ECU 51 that is the target of secure boot (hereinafter referred to as target software) to verify whether or not it has been tampered with. In the following step S3, if the tampering recognition unit 22 detects tampering of the target software, the processing proceeds to step S10. If the tampering recognition unit 22 does not detect tampering of the target software, the processing proceeds to step S4, where the current tampering monitoring processing ends.
[0029] In step S10, the tampering recognition unit 22 counts up the counter variable CT (CT+1→CT). In the following step S12, the tampering recognition unit 22 determines whether the vehicle 100 is in an activated state, and if it is in an activated state, proceeds to step S20, and if it is not in an activated state (if it is in a standby state), proceeds to step S20.
[0030] In step S12, the tampering recognition unit 22 determines whether the counter variable CT is equal to or greater than the first determination count X1. If the counter variable CT is equal to or greater than the first determination count X1, the tampering recognition unit 22 confirms the recognition of tampering of the target software and proceeds to step S13, whereas if the counter variable CT is less than the first determination count, the tampering recognition unit 22 proceeds to step S2.
[0031] In step S13, the tampering notification unit 25 displays a tampering notification screen on the display 5 or the display unit of the user terminal 90, as described above. In the following step S14, the tampering response unit 23 prohibits the startup of the vehicle 100 as a first boot process against the tampering. The user U visually checks the tampering notification screen, recognizes that the target software has been tampered with, and requests a road service company or the like to handle the breakdown of the vehicle 100.
[0032] By processing steps S2, S3, S10 to S14, when tampering with the target software is detected consecutively for the first determination number X1 or more, the recognition of tampering with the target software is confirmed, thereby preventing the vehicle 100 from entering a startup prohibition state due to a false detection of tampering.
[0033] In step S20, the tampering recognition unit 22 determines whether the counter variable CT is equal to or greater than the second determination count X2. If the counter variable CT is equal to or greater than the second determination count X2, the tampering recognition unit 22 confirms that the target software has been tampered with and proceeds to step S21 in Fig. 3, whereas if the counter variable CT is less than the second determination count X2, the tampering recognition unit 22 proceeds to step S2.
[0034] Here, the second determination count X2 corresponding to when the vehicle 100 is in an activated state is set to a number greater than the first determination count X1 corresponding to when the vehicle 100 is in a standby state. As a result, when the vehicle 100 is in an activated state and the user U is using the vehicle 100 and there is little risk of the vehicle 100 being stolen, it is possible to prevent the use of the vehicle 100 from being interrupted due to a false detection of tampering of the target software, which would result in the boot process of the vehicle 100 being executed.
[0035] 3, the tampering notification unit 25 displays a tampering notification screen on the display 5 or the display unit of the user terminal 90, as described above. In the following step S22, the tampering response unit 23 determines whether the control target of the target software for which tampering has been recognized is a predetermined function. Here, the predetermined function is a function that does not interfere with the running of the vehicle 100 (for example, entertainment functions such as displaying content on the display 5, communication functions by the communication unit 3, air conditioning, connection functions with portable devices via an interface such as USB (registered trademark), etc.).
[0036] If the control target of the target software is a predetermined function, the tampering response unit 23 proceeds to step S30, and if the control target of the target software is not a predetermined function, the tampering response unit 23 proceeds to step S23. In step S23, the tampering response unit 23 executes a second boot process corresponding to the case where the vehicle 100 is in a started state, and the process proceeds to step S4 in FIG.
[0037] As a second boot process, the tampering response unit 23 performs degeneration control such as decelerating the vehicle 100 and inducing the vehicle to stop on the shoulder of the road when the vehicle 100 is traveling, and after the vehicle 100 has stopped, when the vehicle 100 enters a standby state in response to operation of the SS switch 2, performs a process to prohibit the vehicle 100 from starting up.
[0038] In step S30, the falsification response unit 23 determines whether the current position of the vehicle 100 recognized by the moving object position recognition unit 24 is other than a road. If the current position of the vehicle 100 is other than a road, the falsification response unit 23 proceeds to step S22, and if the current position of the vehicle 100 is on a road, the falsification response unit 23 proceeds to step S31.
[0039] In step S31, when vehicle 100 enters a standby state in response to operation of SS switch 2, tampering response unit 23 proceeds to step S32, where it executes the first boot process corresponding to the standby state, similar to step S14 in Fig. 2 described above, and then proceeds to step S4 in Fig. 2. The process of step S30 corresponds to the tampering response suspension process of the present disclosure.
[0040] 3. Other Embodiments In the above embodiment, the tampering recognition unit 22 confirmed the recognition of tampering of the target software when tampering of the target software was detected consecutively by the secure boot process a predetermined number of times or more. In another embodiment, the tampering recognition unit 22 may execute the secure boot process multiple times and confirm the recognition of tampering of the target software when the proportion of the number of times tampering of the target software is detected among the multiple executions is equal to or greater than a predetermined determination proportion. In this case, the second determination proportion corresponding to the case where the vehicle 100 is in the activated state may be set to a proportion greater than the first determination proportion corresponding to the case where the vehicle 100 is in the standby state (first determination proportion<second determination proportion).
[0041] Further, the first determination count, the second determination count, the first determination ratio, and the second determination ratio may be changed according to a predetermined function related to the target software. For example, the first determination count and the second determination count for the target software of the driving control system of the vehicle 100 may be set to be less than the first determination count and the second determination count for the target software related to controls other than the driving control system (target software related to air conditioning, entertainment, etc.). Also, the first determination ratio and the second determination ratio for the target software of the driving control system of the vehicle 100 may be set to be less than the first determination ratio and the second determination ratio for the target software related to controls other than the driving control system (target software related to air conditioning, entertainment, etc.).
[0042] In the above embodiment, the tampering recognition unit 22 sets the second determination count X2 corresponding to the case where the vehicle 100 is in the startup state to be more than the first determination count X1 corresponding to the case where the vehicle 100 is in the standby state (X1 < X2). As another embodiment, the first determination count X1 and the second determination count may be set to the same count. Also, when tampering of the target software is detected by the secure boot process, the recognition of tampering of the target software may be determined without determining the detection count of tampering.
[0043] In the above embodiment, the mobile body position recognition unit 24 is provided, and the tampering countermeasure unit 23 determines in step S30 of FIG. 3 whether the current position of the vehicle 100 is outside a road, and holds the execution of the first boot process in step S32 until the vehicle 100 enters the standby state in step S31. As another embodiment, the mobile body position recognition unit 24 may be omitted and the configuration may be such that the determination in step S30 is not performed.
[0044] 3, the tampering response unit 23 determines whether to suspend execution of the first boot process in step S32 until the vehicle 100 enters a standby state in step S31, depending on the type of control target by the target software. In another embodiment, the determination process in step S22 may be omitted, and execution of the first boot process in step S32 may be suspended until the vehicle 100 enters a standby state in step S31, regardless of the type of control target by the target software.
[0045] In the above embodiment, the tampering notification unit 25 is provided to notify software tampering, but the tampering notification unit 25 may be omitted.
[0046] 1 is a schematic diagram showing the configuration of the mobile object control device 1 divided by main processing content to facilitate understanding of the present invention, but the mobile object control device 1 may also be divided into other categories. Furthermore, the processing of each component may be executed by one hardware unit or by multiple hardware units. Furthermore, the processing of each component shown in FIGS. 2 and 3 may be executed by one program or by multiple programs.
[0047] 4. Configurations supported by the above embodiments The above embodiment is a specific example of the following configuration.
[0048] (Configuration 1) A mobile body control device comprising: a tampering recognition unit that executes a secure boot process to verify whether software stored in a memory unit provided in a mobile body has been tampered with, and recognizes tampering of the software; and a tampering response unit that executes the secure boot process by the tampering recognition unit when the mobile body is in an activated state, and when the tampering recognition unit recognizes tampering of the software related to a specified function of the mobile body, executes a tampering response suspension process that keeps the specified function usable until the mobile body enters a standby state, and disables the use of the specified function after the mobile body enters a standby state. According to the mobile body control device of configuration 1, when software tampering is recognized while the mobile body is in an activated state, the specified software functions are maintained in a state where they can be used until the mobile body enters a standby state, thereby preventing the mobile body from becoming unusable due to a false detection of software tampering.
[0049] (Configuration 2) The mobile control device described in Configuration 1, wherein the tampering recognition unit executes the secure boot process multiple times and determines that the software has been tampered with when tampering is detected consecutively by the secure boot process a predetermined number of times or more, or when the proportion of times tampering is detected among the multiple executions of the secure boot process is a predetermined proportion or more. According to the mobile object control device of configuration 2, the secure boot process is executed multiple times to confirm the recognition of software tampering, thereby reducing the possibility that software tampering will be mistakenly recognized.
[0050] (Configuration 3) The mobile body control device described in Configuration 2, wherein the tampering recognition unit sets the number of judgments when the mobile body is in an activated state to be greater than the number of judgments when the mobile body is in a standby state, and sets the judgment rate when the mobile body is in an activated state to be greater than the judgment rate when the mobile body is in a standby state. According to the mobile body control device of configuration 3, when the mobile body is in an activated state and a user is using the mobile body, and therefore it is assumed that there is a low risk of theft of the mobile body, etc., the possibility of software tampering being mistakenly recognized can be reduced by setting the number of judgments to be higher than when the mobile body is in a standby state, or by setting the judgment ratio to be higher than when the mobile body is in a standby state.
[0051] (Configuration 4) The mobile object control device according to Configuration 2 or 3, wherein the tampering recognition unit changes the number of times of determination and the determination rate according to the predetermined function. According to the mobile object control device of configuration 4, by changing the number of judgments and the judgment ratio appropriately according to the predetermined function related to the software, it is possible to reduce the possibility that software tampering will be mistakenly recognized.
[0052] (Configuration 5) A mobile body control device described in any one of configurations 1 to 4, wherein when the mobile body is in an activated state, the tampering response unit executes the secure boot process by the tampering recognition unit and the tampering recognition unit recognizes tampering of the software related to the specified function of the mobile body, and the tampering response unit determines whether to execute the tampering response suspension process depending on the type of the specified function. According to the mobile body control device of configuration 5, it is possible to determine whether or not to execute tamper response suspension processing depending on, for example, whether the type of specified function related to the software contributes to controlling the movement of the mobile body.
[0053] (Configuration 6) A mobile body control device according to any one of configurations 1 to 5, wherein the mobile body is a vehicle and is provided with a mobile body position recognition unit that recognizes the position of the mobile body, and the tampering response unit, when the mobile body is in an activated state and the mobile body position recognition unit recognizes that the mobile body is located outside a road, executes the secure boot process by the tampering recognition unit, and when the tampering recognition unit recognizes tampering of the software related to the specified function of the mobile body, disables the use of the specified function without executing the tampering response suspension process. According to the mobile control device of configuration 6, if the vehicle is parked in a parking space or the like other than on a road, and it is expected that the inconvenience to the user will be minimal even if the use of the specified functions related to the software in which tampering has been detected is disabled, the use of the specified functions can be immediately disabled and tampering response processing can be performed.
[0054] (Configuration 7) A mobile body control device described in any one of configurations 1 to 6, which includes a tampering notification unit that outputs warning information about tampering with the software from an alarm device used in the mobile body when tampering with the software is recognized by the tampering recognition unit. According to the mobile object control device of configuration 7, it is possible to notify the user that software tampering has been recognized, and to urge the user to take action to address the tampering.
[0055] (Configuration 8) A mobile body control device described in any one of configurations 1 to 7, which is provided with a tampering notification unit that, when the tampering recognition unit recognizes tampering of the software, sends warning information about the tampering of the software to a user terminal used by a user of the mobile body. According to the mobile object control device of configuration 8, it is possible to notify the user that software tampering has been recognized, and to urge the user to take action to address the tampering.
[0056] (Configuration 9) A mobile body control method executed by a computer, comprising: a tampering recognition step of executing a secure boot process to verify whether software stored in a memory unit provided in the mobile body has been tampered with, and recognizing tampering with the software; and a tampering response step of executing a tampering response suspension process to maintain a state in which the specified function can be used until the mobile body enters a standby state, when the secure boot process is executed by the tampering recognition step when the mobile body is in a booted state and tampering with the software related to a specified function of the mobile body is recognized by the tampering recognition step, and disabling the use of the specified function after the mobile body enters a standby state. By executing the mobile object control method of configuration 9 by a computer, the same effects as those of the mobile object control device of configuration 1 can be obtained.
[0057] (Configuration 10) A program that causes a computer to function as a tampering recognition unit that executes a secure boot process to verify whether software stored in a memory unit provided in a mobile body has been tampered with, and recognizes tampering of the software, and a tampering response unit that executes a tampering response suspension process that maintains the use of the specified function until the mobile body enters a standby state when the secure boot process is executed by the tampering recognition unit and the tampering recognition unit recognizes tampering of the software related to a specified function of the mobile body when the mobile body is in a started state, and disables the use of the specified function of the mobile body after the mobile body enters a standby state. By executing the program of configuration 10 by a computer, the configuration of the mobile object control device of configuration 1 can be realized. [Explanation of symbols]
[0058] 1...mobile object control device, 2...SS switch, 3...communication unit, 4...navigation device, 5...display, 10...central ECU, 20...processor, 21...communication control unit, 22...tampering recognition unit, 23...tampering response unit, 24...mobile object position recognition unit, 25...tampering notification unit, 30...memory, 31...program, 50 (50a, 50b)...gateway ECU, 51 (51a to 51f)...local ECU, 71 to 73...in-vehicle equipment, 90...user terminal, 100...vehicle (mobile object), 200...communication network, 210...mobile object management server, U...user
Claims
1. a tampering detection unit that executes a secure boot process to verify whether software stored in a storage unit provided in the mobile object has been tampered with, and detects tampering of the software; a tamper response unit that, when the secure boot process is executed by the tamper recognition unit while the mobile body is in an activated state and the tamper recognition unit recognizes tampering of the software related to a predetermined function of the mobile body, executes a tamper response suspension process that maintains a usable state of the predetermined function until the mobile body enters a standby state, and disables the use of the predetermined function after the mobile body enters the standby state; A mobile object control device comprising:
2. The tampering recognition unit executes the secure boot process multiple times, and when tampering is detected consecutively by the secure boot process a predetermined number of times or more, or when the ratio of the number of times tampering is detected among the number of times the secure boot process is executed multiple times is a predetermined ratio or more, it determines that the software has been tampered with. The mobile object control device according to claim 1 .
3. The tampering recognition unit The number of determinations when the moving body is in an activated state is set to be greater than the number of determinations when the moving body is in a standby state; The determination ratio when the moving body is in an activated state is set to be larger than the determination ratio when the moving body is in a standby state. The mobile object control device according to claim 2 .
4. The tampering recognition unit changes the number of times of judgment and the judgment ratio according to the predetermined function. The mobile object control device according to claim 2 or 3.
5. When the secure boot process is executed by the tamper recognition unit while the mobile body is in an activated state and the tamper recognition unit recognizes tampering of the software related to the predetermined function of the mobile body, the tamper response unit determines whether to execute the tamper response suspension process according to the type of the predetermined function. The mobile object control device according to any one of claims 1 to 3.
6. the moving body is a vehicle, a mobile object position recognition unit that recognizes the position of the mobile object, When the mobile object is in an activated state and the mobile object location recognition unit recognizes that the mobile object is located outside a road, the tampering response unit executes the secure boot process and, if the tampering recognition unit recognizes that the software related to the predetermined function of the mobile object has been tampered with, disables use of the predetermined function without executing the tampering response suspension process. The mobile object control device according to any one of claims 1 to 3.
7. and a tampering notification unit that outputs warning information about the tampering of the software from a notification device used in the mobile object when the tampering recognition unit recognizes that the software has been tampered with. The mobile object control device according to any one of claims 1 to 3.
8. and a tampering notification unit that, when the tampering recognition unit recognizes that the software has been tampered with, transmits warning information about the tampering of the software to a user terminal used by a user of the mobile object. The mobile object control device according to any one of claims 1 to 3.
9. A computer-implemented mobile object control method, a tampering recognition step of executing a secure boot process to verify whether or not software stored in a storage unit provided in the mobile object has been tampered with, and recognizing the tampering of the software; a tampering response step in which, when the mobile body is in an activated state, the secure boot process is executed by the tampering recognition step, and when tampering of the software related to a predetermined function of the mobile body is recognized by the tampering recognition step, a tampering response suspension process is executed to maintain a usable state of the predetermined function until the mobile body enters a standby state, and after the mobile body enters the standby state, the predetermined function is made unusable; A mobile object control method comprising:
10. Computer, a tampering detection unit that executes a secure boot process to verify whether software stored in a storage unit provided in the mobile object has been tampered with, and detects tampering of the software; a tamper response unit that, when the secure boot process is executed by the tamper recognition unit while the mobile body is in an activated state and the tamper recognition unit recognizes tampering of the software related to a predetermined function of the mobile body, executes a tamper response suspension process that maintains a usable state of the predetermined function until the mobile body enters a standby state, and disables the use of the predetermined function of the mobile body after the mobile body enters the standby state; A program that makes it work.
Citation Information
Patent Citations
Tampering detection system and electronic control unit
JP2014151720A
Information processing system
JP2017167916A
Control system
WO2021240700A1
Information processing device, and information processing method
JP2021002168A
Cited By
Thermal energy storage system
US12474127B2